SUSE-SU-2022:2893-1
Dashboard / Vulnerabilities / SUSE-SU-2022:2893-1
SUSE-SU-2022:2893-1
Summary: Security update for postgresql10
Details: This update for postgresql10 fixes the following issues: - Upgrade to 10.22: - CVE-2022-2625: Fixed an issue where extension scripts would replace objects not belonging to that extension (bsc#1202368). - Upgrade to 10.21: - CVE-2022-1552: Confined additional operations within 'security restricted operation' sandboxes (bsc#1199475). - Upgrade to 10.20 (bsc#1195680) - Add constraints file with 12GB of memory for s390x as a workaround (boo#1190740) - Upgrade to version 10.19 (bsc#1192516): - CVE-2021-23214: Made the server reject extraneous data after an SSL or GSS encryption handshake - CVE-2021-23222: Made libpq reject extraneous data after an SSL or GSS encryption handshake - Fix for build with llvm12 on s390x. (bsc#1185952) - Re-enable 'icu' for PostgreSQL 10. (bsc#1179945) - Add postgresqlXX-server-devel as a dependency for postgresql13-server-devel. (bsc#1187751) - Upgrade to version 10.18. (bsc#1190177)
References: https://www.suse.com/support/update/announcement/2022/suse-su-20222893-1/, https://bugzilla.suse.com/1179945, https://bugzilla.suse.com/1183168, https://bugzilla.suse.com/1185952, https://bugzilla.suse.com/1187751, https://bugzilla.suse.com/1190177, https://bugzilla.suse.com/1190740, https://bugzilla.suse.com/1192516, https://bugzilla.suse.com/1195680, https://bugzilla.suse.com/1199475, https://bugzilla.suse.com/1202368, https://www.suse.com/security/cve/CVE-2021-23214, https://www.suse.com/security/cve/CVE-2021-23222, https://www.suse.com/security/cve/CVE-2022-1552, https://www.suse.com/security/cve/CVE-2022-2625
Affected packages
Package
Name: postgresql
Purl: pkg:rpm/suse/postgresql&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOS
Affected ranges
Type: ECOSYSTEM
Events:
